Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12F51F1A0D015AC335103E2E467D4AB8B3687C715C687290967F083AC2EE3C5DDF66669 |
|
CONTENT
ssdeep
|
48:LIVhhzJzZyd9CPTOVyUhxnja26YXAPy9uilLM7aynBLP5ut16:LMLzZyGPKhxnebBy9ui9MeSFxu6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
83e67f0103039bfe |
|
VISUAL
aHash
|
3f3f3f3f3f3f3f3f |
|
VISUAL
dHash
|
d0c6ccd8d0d0d0d0 |
|
VISUAL
wHash
|
3f233f3f3f0f0000 |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
808c9890a0808080,f184acb6b6ac84f3,0e71710e20000000 |
⢠Threat: Credential Phishing
⢠Target: Microsoft Outlook users
⢠Method: Impersonation through a fake login page
⢠Exfil: https://webernets.online/owa/auth.owa
⢠Indicators: Mismatched domain, JavaScript obfuscation, form submission to different domain
⢠Risk: HIGH
The attacker is attempting to steal user credentials by mimicking the Microsoft Outlook login page and redirecting the submitted form data to a malicious server.
The use of 'document.write' and other obfuscation techniques make the attack code harder to detect.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain